Reviewing ACC Seats and User Roles

Avid Content Core includes the concept of seats and roles. If you are familiar with MediaCentral Cloud UX, you can loosely associate the concept of seats with licenses, and roles with entitlements. Whenever a user signs in to ACC, they consume a seat in your subscription. Roles help administrators manage what kind of seats are consumed and the permissions associated with each user by assigning roles to IDP user groups.

Avid Content Core allows you to oversubscribe seats as necessary. For example, you can purchase 250 Editor seats and assign the Editor role to a user group that includes 500 people. While this workflow is allowed, your organization could be subject to over-subscription fees if users consume more licenses than are included in your Avid Content Core subscription.

Description of Roles

The following sections detail the expected use case and permissions for each role type. Note that some roles are associated with exclusive access to some areas of the user interface. For example, the Cutting Room Administrator includes access to the Web Editor Settings app only. If you assign a user group to this role only, users within that group can sign in to Avid Content Core, but their user interface will be extremely limited. All other areas of the UI are hidden for this user.

If a user belongs to multiple groups with varying role permissions, the total access to Avid Content Core is cumulative of those roles. For example, you might have a user that is included in a user group that is assigned to the Editor role, while also being in a group that is assigned to an administrator-level role. That user can perform any task that is allowed by both role types.

High-privilege administrative roles intentionally do not include content workflow permissions. For example a Tenant Administrator cannot edit video assets or manage editorial tasks, unless they are also assigned a content-facing role. This separation is deliberate — it enforces separation of duties and limits the blast radius of a compromised or misused admin account. Users should be assigned only the roles they need to do their job, and high-privilege roles should be assigned to a minimal number of trusted individuals.

Roles can generally be divided into two categories:

  • User Roles: Viewer, Journalist, Approver, Editor, Collection Manager, Workflow Administrator

  • High-Privilege Roles: Tenant Administrator, Cutting Room Administrator

These roles are static and cannot be customized. You cannot create new role types in this release of Avid Content Core.

Approver

Intended for editors, producers, or compliance reviewers who are responsible for evaluating and approving content at defined stages of a production workflow.

Collection Manager

This role is intended for future use and is not applicable to this version of Avid Content Core.

Cutting Room Administrator

Allows the associated user group access the Web Editor administrator settings. This dedicated role gives you the flexibility to great access to this specific area of the administrator settings. This might be useful in case you have select users that require the ability to mange social media profiles, but they do not need any additional administrative-level access.

Editor

This role is intended for those that need to collect assets and use the Web Editor to create sequences that can be published to social media destinations.

Journalist

Searches, retrieves, edits proxy clips. Publishes to social media.

Tenant Administrator

This role provides access to the ACC Control Panel for tenant administration. Following best security practices, the group that is assigned to this role should not be associated with any other role.

Viewer

This role provides read-only access to limited areas of Avid Content Core. This role is typically assigned to reviewers, junior staff, or anyone that needs to view content, but not edit or alter it.

Workflow Administrator

Oversight and management of editorial workflows and media processing jobs across the tenant. Intended for production managers or operations staff who need visibility and control over tasks, ingest jobs, and proxy/transcoding queues — without needing access to tenant configuration.

Adding and Removing User Roles

After you have configured your Identity Provider settings, you can assign your IDP groups to Avid Content Core roles. It is possible that your organization includes groups that do not need access to Avid Content Core. If you do not assign a role to these user groups, the members of that group are denied access to Avid Content Core.

If you make a change to your role assignments, those changes are applied the next time that the user signs into Avid Content Core. Changes are not applied to the user in "mid-session".

n If you have not organized your users into logical groups, it might be beneficial to do so now. If your IDP user groups are well organized, then the Avid Content Core role management process becomes much easier.

To configure user roles:

  1. Click the Role Mappings tab in the ACC Control Panel header.

  2. Click the Create Mapping button.

  3. Type the name of a user group into the IdP Group Name field.

  4. Select a role type from the menu.

  5. Click the Create Mapping button to save your role assignment.

  6. Repeat these steps as many times as necessary to configure your desired roles.

    It is possible to associate a single role with multiple groups if desired. However, you must complete these assignments one at a time.

  7. Finally, confirm that your credentials and user roles are working by signing into Avid Content Core.

To remove a role from a user group:

  1. Click the Role Mappings tab in the ACC Control Panel header.

  2. Click the Delete button to the right of any group to role mapping.